request objects should have iat and exp

Issue #152 resolved
Joseph Heenan created an issue

There doesn't seem to be anything in FAPI part 2 that requires request objects to have iat and exp fields.

I believe this would allow an attacker to replay authorisation requests much later on. I'm not sure that's desirable.

Should we be mandating iat & exp?

Comments (10)

  1. Log in to comment